Skip to main content

CVE detail

CVE-2026-42533

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS 9.2 · CriticalBuzz score 48.61 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 48.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 25.6 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 5.0
Mention score
25.6
12 evidence mentions in the snapshot
Diversity score
18.0
5 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
5.0
1 repos · best confidence 0.99
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
8
within the 30d window
Peak daily
3
highest bucket

Evidence

Source links by recency

Newest mentions first
12 source links · newest first
  • lized AI Model for Vulnerability Hunting Check Point patches actively exploited SmartConsole authentication bypass flaw CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities cata

    newssecurityaffairs.comJul 26, 2026, 11:42 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 23, 2026, 11:44 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 22, 2026, 8:51 AM
  • Information published.

    vendormsrc.microsoft.comJul 22, 2026, 8:41 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 21, 2026, 6:25 PM
  • on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo

    newsthehackernews.comJul 20, 2026, 1:32 PM
  • F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow

    newssecurityaffairs.comJul 20, 2026, 9:50 AM
  • Contact me MUST READ Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! | CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign | Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appl

    newssecurityaffairs.comJul 20, 2026, 8:21 AM
  • ets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of

    newsthehackernews.comJul 19, 2026, 8:42 PM
  • OpenSSL Fixes HollowByte Memory Exhaustion BugSecurity Affairs

    Contact me MUST READ Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! | CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign | Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appl

    newssecurityaffairs.comJul 18, 2026, 6:24 PM
  • nounced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP. The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process. “A vulnerability exists i

    newswww.securityweek.comJul 16, 2026, 9:20 AM
  • No excerpt available.

    Vendor Advisorymy.f5.comJul 15, 2026, 3:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 0 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence